SFTP Vulnerability in SCALANCE LPE9403 by Siemens
CVE-2025-27395

8.6HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 March 2025

Summary

A security flaw has been identified in the SCALANCE LPE9403 device, where the SFTP functionality does not adequately restrict the scope of accessible files and the privileges assigned. This weakness could allow an authenticated, highly-privileged remote attacker to gain unauthorized read and write access to arbitrary files, potentially compromising the system's integrity and confidentiality. It is crucial for users to assess their deployment and apply necessary remediations to secure their environments.

Affected Version(s)

SCALANCE LPE9403 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.